Darktrace /NETWORK Integration

Note: This integration requires Cisco XDR Advantage or Cisco XDR Premier licensing tier.

Darktrace /NETWORK is a Network Detection and Response (NDR) offering. In Cisco XDR, we enable Darktrace users to leverage it in investigations and for response actions. In investigate, Darktrace can respond with detection details for queried hostnames, IP and MAC addresses, and Darktrace DeviceIDs. The Darktrace integration can also be used in Automation and from the pivot menu to quarantine and unquarantine devices by hostname, Darktrace DeviceID, and IP or MAC address.